Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
drivesafely
New Contributor

FG60E SSLVPN (-14) error

Hello,

We have FG60E model with version 7.0.7 (build 0367) running.

We have configure Remote SSL VPN and when we try to connect, we get the error as follows,

"Unable to establish the VPN connection. The VPN server may be unreachable. (-14)"

We checked the option under fullacces, the "Host Check" option not enabled. (SSL VPN Portals -> Tunnel Mode -> Host Check).

We tried with Forticlient version 7.4.0.1658 and 6.4.9.1797 and getting same error.

How to check if there are any logs in the firewall for this kind of error?

Can someone guide on how to resolve this issue?

Thanks

8 REPLIES 8
ffuchs
New Contributor

Hi,

did you check
diag debug application sslvpn -1

diag debug enable
?
could help to identify the issue. TLS version? Guess the free FortiClient?

Not pretty sure in which version of the FortiOS SSLVPN is disabled at the 7.0.x, but i guess its not 7.0.7. Guess it´s a later release

 

Greetings

FCP Network Security | FCP Security Operations | FCSS Network Security | FCSS SASE | FCT
FCP Network Security | FCP Security Operations | FCSS Network Security | FCSS SASE | FCT
drivesafely

Hi,

I will check the debug option. Since i have not used the debug earlier, can you confirm this is correct,

I will run the following from CLI

diag debug application sslvpn -1

diag debug enable

Then try to connect to vpn and would get the logs on screen and the Ctrl+C to stop debug?

 

We are using the free forticlient for vpn only. Does it have anything to do with it?

Please guide more details on what to check with regards to TLS version in the firewall.

 

Thanks again.

 

ffuchs

correct

 

but instead of Ctrl+C its

diag debug disable

FCP Network Security | FCP Security Operations | FCSS Network Security | FCSS SASE | FCT
FCP Network Security | FCP Security Operations | FCSS Network Security | FCSS SASE | FCT
Dhruvin_patel

Greetings,

 

From the note, you get this error "Unable to establish the VPN connection. The VPN server may be unreachable. (-14)"

 

This is related to the reachability issue. Try to ping the remote address configured in the sslvpn setting on Forticlient from the command prompt. Check the reachability. 

 

This community article will give different possibilities that could cause the issue. steps, https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Possible-reasons-for-FortiClient-SSL...

 

Regards!

If you have found a solution, please like and accept it to make it easily accessible for others.

Dhruvin Patel
DPadula
Staff
Staff

Hi drivesafely
The following link list the most common messages that you might seen when there is an issue with the SSL VPN.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Possible-reasons-for-FortiClient-SSL...


Do you have a technical reason to use version 7.0.7? Why don't upgrade to the latest version?

This link shows the differences between free and paid version of FortiClient.
https://docs.fortinet.com/document/forticlient/6.2.2/administration-guide/269675/feature-comparison-...

 

drivesafely

Hello All,

Thanks for the response and useful links.

As per the troubleshooting article link, "The -14 error of around 80% could be because of a user/group mismatch between the SSL VPN authentication rules and the Firewall policy for SSL VPN." We shall check this and revert.

We shall upgrade the firmware to latest version. The path to upgrade for FG60E model should be as follows,
7.0.7 F build 0367
7.2.3 F build 1262
7.4.0 F build 2360
7.4.2 F build 2571
7.4.4 F build 2662
Hope the above path is correct.

As for the Free vs Paid versions of forticlient, i do not see that this error is related to it?

Thanks,

DPadula

Hi Drivesafely 

 

You are in the right path, check your SSL VPN authentication rules and the Firewall policy as described by the article. Are you filtering the firewall rule based on a specific group of users?

The upgrade path is correct, I checked via https://docs.fortinet.com/upgrade-tool/fortigate. It is exactly as you pasted.

drivesafely

Hello DPadula,

In SSL-VPN-Settings, we have added a group consisting of all VPN local users in Authentication/Portal Mapping section with full-access.

In the firewall policy we have for VPN, we have added individual VPN users (belonging to the VPN group) and SSLVPN Tunnel Addr group.

Thanks,

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors